Datenschutz

I Overview

If we may welcome you as a customer or business partner, or if you use our Nuseum application, please read from Section III.

If you visit our website, please read from Section II.

II What data do we process when you visit our website?

Welcome to our website! Please take a moment to understand how we process your personal data when you visit our website (Art. 13, Art. 14 GDPR; § 165 para. 3 TKG).

When visiting our website, the following data may be processed:

Processing this data is necessary to ensure the security of website operations and to maintain the website’s functionality from a technical standpoint. This data is collected in part through technical cookies, which are only used to the necessary extent (§ 165 para. 3 TKG). Processing this data is justified by our legitimate interest in operating our website (Art. 6 para. 1 lit. f GDPR).

For the operation of our website, it may be necessary to disclose your data to the following recipients:

Data Recipient: Google LLC (Google Cloud & Folder; Google Workspace; Google Analytics; Google Calendar)
Purpose of Data Processing: Email and chat server; storage of internal documents; marketing and offer optimization; communication
Legal Basis for Data Processing: Predominantly legitimate interest (Art. 6 para. 1 lit. f GDPR), consent regarding Google Analytics (Art. 6 para. 1 lit. a GDPR), and contractual necessity (Art. 6 para. 1 lit. b GDPR)
Business Location: USA
Secure Third-Country Transfer: Google LLC is listed under the EU-US Data Privacy Framework (HR & Non-HR data)

Data Recipient: HubSpot, Inc. (CRM)
Purpose of Data Processing: Sales data management (contact and sales activities)
Legal Basis for Data Processing: Predominantly legitimate interest (Art. 6 para. 1 lit. f GDPR)
Business Location: USA
Secure Third-Country Transfer: HubSpot is listed under the EU-US Data Privacy Framework (Non-HR data)

Data Recipient: Wix.com, Limited
Purpose of Data Processing: Website hosting
Legal Basis for Data Processing: Predominantly legitimate interest (Art. 6 para. 1 lit. f GDPR)
Business Location: Israel
Secure Third-Country Transfer: The European Commission has issued an adequacy decision recognizing Israel’s data protection level as sufficient.

 

II.1. Overview of „Technical“ Cookies Used

The above-mentioned data is stored via so-called „cookies.“ Cookies are text files stored on your computer that enable the analysis of website usage. They help recognize and temporarily store data of website visitors. We only use cookies to the extent necessary to communicate with you via the website.

These technical cookies are activated as soon as you visit our website.

The following cookies are used on our platform based on our predominantly legitimate interest (Art. 6 para. 1 lit. f GDPR):

II.2. Overview of „Advertising Cookies“

In addition to the above-described „technical cookies,“ we do not use any cookies, particularly no advertising cookies.

III. What data do we process when you are a customer, business partner, or use our application(s)?

As part of our business relationship with customers and business partners, and the provision of the Nuseum application for users, we process data due to contractual obligations (execution of the contractual relationship, pre-contractual obligations, service billing, document dispatch, communication, application provision) and legal obligations (legally required retention pursuant to § 132 BAO) (Art. 6 para. 1 lit. b and c GDPR), as well as due to our legitimate interests or those of third parties (Art. 6 para. 1 lit. f GDPR), namely:

If you do not provide us with this data, we cannot process your business case.

In certain cases, we may process your data based on your voluntary, explicit consent (Art. 6 para. 1 lit. a GDPR).

 

III.1. What data

 is processed in connection with a business relationship?

For handling and fulfilling business relationships with our customers and suppliers, the following personal data or categories of personal data are processed:

III.2. What data is processed when using the Nuseum application?

When using the Nuseum application (“application”), the following personal data or categories of personal data are processed:

In general, no personal data should be entered into the application.

 

IV How long do we store your data?

We store your data only as long as necessary for the purposes for which it was collected. Legal retention periods must be considered (e.g., contracts and documents related to tax law must be stored for seven years, § 132 BAO). In justified cases, such as asserting or defending legal claims, we may store data for up to 30 years after the business relationship ends.

Data from interested parties is stored for up to one year from the last contact.

 

V Who may receive your data?

As part of our business relationship and the use of the application, it may be necessary for us to transfer your data to the following recipients:

Recipient: Google LLC

Services Used: Google Cloud & Folder, Google Workspace, Google Analytics, Google Calendar
Purpose of Data Processing: Email and chat servers, storage of internal documents, marketing and optimization of the offering, contact management
Legal Basis for Data Processing:

Recipient: HubSpot, Inc.

Services Used: CRM
Purpose of Data Processing: Sales data management (contact and sales activities)
Legal Basis for Data Processing: Predominantly legitimate interest (Art. 6(1)(f) GDPR)
Business Location: USA
Secure Third-Country Transfer: HubSpot is listed under the EU-US Data Privacy Framework (Non-HR data).

Recipient: Amazon.com, Inc.

Services Used: Amazon AWS
Purpose of Data Processing: Hosting of the software infrastructure (Copilot & CuratorSpace)
Legal Basis for Data Processing:

VI Collection of Data from Other Sources (Art. 14 GDPR)

For the provision of the Nuseum application, the system is trained by the museum or cultural institution for specific use cases. In this process, personal data may also be processed.

For the purpose of initiating contact with relevant stakeholders in the cultural sector, personal data may also be processed:

 

VII Are automated decision-making or profiling processes used?

No automated decision-making or profiling takes place in our company.

 

VIII What rights do you have regarding data processing?

You have the right to:

 

IX Which rights to complain do you have?

If data processing breaches your rights, you can contact us (via mail or email). We aim to process your inquiry as soon as possible. You also have the right to complain to the authority responsible for you.

The address of the Austrian Data Protection Authority is:

Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna

 

X How can you contact us?

For questions regarding the processing of your data, you can contact our data protection coordinator as stated below.

XI Controller

Controller according to Art 4 Z 7 GDPR is:

KOHATECH FlexCo
Rabensburgerstraße 17
1020 Vienna, Austria
Email: [email protected]

Note: If a museum or cultural institution uses the Nuseum application, KOHATECH FlexCo acts as a processor, while the museum or institution is the controller.

 

Last Updated: 1st of March 2025